Grafana

Grafana

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 13.10.2022 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:56

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a ma...

  • EPSS 0.15%
  • Veröffentlicht 22.09.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:12:17

Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only u...

  • EPSS 0.88%
  • Veröffentlicht 20.09.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:12:03

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and ga...

  • EPSS 0.94%
  • Veröffentlicht 15.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:54

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which pro...

  • EPSS 48.06%
  • Veröffentlicht 15.07.2022 12:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:53

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker c...

Exploit
  • EPSS 17.04%
  • Veröffentlicht 17.06.2022 13:15:16
  • Zuletzt bearbeitet 21.11.2024 07:06:05

Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

Exploit
  • EPSS 67.37%
  • Veröffentlicht 06.06.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 07:06:05

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign erro...

  • EPSS 0.09%
  • Veröffentlicht 20.05.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:58:37

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerabilit...

  • EPSS 0.47%
  • Veröffentlicht 20.05.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:40

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mod...

  • EPSS 0.26%
  • Veröffentlicht 12.04.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:09

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization...